ProBackend
cloud security incidents
1 hour ago7 min read

Solana Blockchain C2 Infrastructure: What Every Security & Compliance Analyst Needs to Know

Threat actors now use the Solana blockchain to hide command-and-control server addresses inside torrent-delivered malware, while campaigns like Star Blizzard's RedFlick automate delivery. Here's why that changes detection, response, and your incident playbook.

Solana Blockchain C2 Infrastructure and the Security & Compliance Analyst

Domain takedowns used to be reliable. A registrar flips a switch, a hosting provider suspends the VPS, and the botnet goes dark within hours. That model is dying. Threat actors now use the Solana blockchain to store command-and-control (C2) server addresses, making infrastructure more resilient and disrupting familiar takedown playbooks.

For a security & compliance analyst, this shift changes what to monitor: a public blockchain lookup can lead malware to infrastructure that is not directly hosted on-chain. The chain may provide the address, while conventional network infrastructure still handles C2 traffic. Blockchain-based address discovery is therefore not, by itself, proof that a particular endpoint is malicious; analysts need to correlate endpoint behavior, network connections, and incident context.

The Solana technique does not arrive in isolation. Reporting across the last year shows attackers investing in two complementary forms of resilience: infrastructure that survives takedowns (the blockchain C2 lookups described here) and delivery chains that survive user scrutiny by requiring less manual interaction from the victim. Understanding both is what turns a fragmented alert into a defensible incident narrative.

Why attackers use Solana for C2 discovery

Malware can query blockchain transaction data or related records to retrieve a server address. Because blockchain data is distributed and difficult to alter or remove, defenders may not be able to disable the lookup simply by requesting a takedown from a hosting provider. The result is added resilience for attackers, not invisibility: endpoint activity and subsequent network connections remain useful detection opportunities.

There is also a cost-and-logistics argument that analysts should appreciate. Renting servers and registering domains creates vendor records and payment trails; posting a value to a public chain creates almost none, and rotating to a new address only requires publishing a new transaction. If one C2 server is seized, the malware can simply read a different record and move on. The same transaction that empowers the attacker, however, is a permanent, publicly analyzable artifact—defenders can also read the chain, and a recovered transaction reference becomes durable evidence for tracking an operation over time.

Reports describe malware distributed through torrents for popular films using this technique. Users may believe they are downloading a media file, while running a malicious payload. Treat torrent-delivered installers and media files as an exposure route to investigate, without assuming every torrent or blockchain lookup represents this specific campaign.

The delivery side: low-interaction infection chains such as RedFlick

While blockchain C2 hardens the back end of an operation, recent campaigns show equal energy spent on the front end. In September 2026, Microsoft researchers described a Russian state actor known as Star Blizzard using a delivery tactic dubbed "RedFlick" to deploy its CosmicPulse backdoor. The underlying techniques are not exotic; what matters is how the chain was assembled so that a single careless click sets everything else in motion automatically.

A RedFlick attack starts with a phishing email—an invitation, for example—followed by a second message carrying a password-protected ZIP or RAR archive. The archive contains a VHDX virtual disk holding an LNK shortcut disguised as a PDF. Opening it silently launches a command in a hidden window while displaying a decoy PDF to the victim, who sees exactly what they expected to see.

That command downloads an MSI installer which creates three scheduled tasks disguised as legitimate maintenance components, each with a narrow role: one sends the computer, network, and username details to the attackers and can execute a remote DLL; a second prepares Windows' WebDAV functionality so remote resources can be accessed like file paths; a third uses control.exe to run the next-stage payload. Splitting the work across separate tasks helps the attacker evade detection at different stages of the attack. The next stage—a downloader Microsoft calls NOROBOT and BAITSWITCH, delivered as a Control Panel applet (.cpl)—fetches the backdoor itself, in one observed case by retrieving a bundled Python runtime and using a bootstrapper that decodes an AES-encrypted payload key from the registry.

The operational lesson generalizes well beyond this one actor. Microsoft reported at least 13 large-scale phishing campaigns this year hitting more than 100 organizations, primarily in the United States and United Kingdom, focused on entities supporting Ukraine. Where earlier ClickFix-style attacks required victims to perform multiple manual steps, RedFlick needs only the opening of a malicious shortcut. A password-protected archive defeats some email scanning, a virtual disk container defeats some reputation checks, and role-split scheduled tasks blur into normal Windows housekeeping. For a security & compliance analyst, the pattern to internalize is that each layer of a modern campaign is chosen to defeat one specific control—not to be clever overall.

Detection priorities for security and compliance analysts

Correlate endpoint telemetry with DNS and outbound network activity. Look for suspicious processes that access Solana-related services and then connect to unusual hosts, especially when the behavior follows execution of an untrusted download. Use endpoint detection controls, egress monitoring, and threat intelligence to investigate the full sequence rather than blocking blockchain traffic indiscriminately.

The RedFlick chain illustrates which primitives deserve monitoring regardless of which campaign you are chasing: creation or mounting of VHDX files from mail or browser processes; LNK execution from removable or disk-image paths spawning hidden command windows; msiexec installing packages outside change control; new scheduled tasks with plausible-sounding maintenance names; control.exe or .cpl execution; and unexpected interpreter runtimes such as Python appearing in user-writable directories. None of these is decisive alone—the "System Health Monitor" task that reads benign on a patched workstation is exactly why you correlate rather than react.

Preserve relevant timestamps, process trees, network indicators, and the blockchain record or transaction reference observed during analysis. Establish whether the retrieved value maps to a destination actually contacted by the device, and check whether other endpoints show the same sequence. This evidence supports a defensible incident timeline and helps distinguish legitimate blockchain use from malware activity.

Cloud security incident response playbook

If an endpoint shows the sequence, isolate it according to your incident procedures, preserve forensic evidence, and identify the downloaded file and its execution path. Hunt for the same indicators across managed devices; review proxy, DNS, firewall, and endpoint logs for related connections. Block confirmed malicious destinations and hashes through your approved controls, while validating that containment does not disrupt legitimate business use.

Assess whether credentials or cloud sessions were exposed. If evidence indicates account compromise, revoke sessions, reset affected credentials, and review sign-in and audit activity, including Microsoft 365 where relevant. Persistence checks should extend beyond the classic autorun locations to scheduled tasks and WebDAV configuration changes, since low-interaction chains like RedFlick deliberately hide there. Document scope, decisions, and evidence retention for security and compliance review. Restore affected systems only after the initial access route and persistence have been addressed.

Prevention layers map directly onto the observed mechanics: phishing-resistant authentication and Conditional Access policies to blunt credential phishing, email filtering configured to treat password-protected archives and external links to disk images as high risk, EDR held in block mode so malicious artifacts are stopped even when antivirus signatures miss them, and out-of-band verification of suspicious messages using established contact details rather than any reply path included in the message itself.

Practical controls and analyst takeaway

Reduce exposure by restricting untrusted downloads, using application control where appropriate, and ensuring endpoint protections and logging are enabled. Create an incident-response procedure for unusual outbound lookups that accounts for both the blockchain query and the destination ultimately contacted. Avoid treating a blockchain provider or transaction as the final C2 endpoint unless telemetry supports that conclusion.

Solana can make C2 address discovery harder to disrupt, but it does not remove the observable behavior around malware execution and network communication. The same holds for automated delivery chains: they remove human steps, not telemetry. For security and compliance analysts, correlating those signals—and preserving evidence—offers a more reliable response than relying on domain takedowns alone.

Related reading: Brickstorm and persistent access to Microsoft 365

Sources: Dark Reading — cybercriminals hiding malware in torrents for popular films; BleepingComputer — Russian state hackers use new RedFlick technique to push malware

solana blockchain c2 infrastructure and the security &

More blogs